Skip to content

Commit 723693e

Browse files
committed
liballoc: introduce String, Vec const-slicing
This change `const`-qualifies many methods on Vec and String, notably `as_slice`, `as_str`, `len`. These changes are made behind the unstable feature flag `const_vec_string_slice` with the following tracking issue: rust-lang#129041
1 parent 3394557 commit 723693e

File tree

4 files changed

+76
-30
lines changed

4 files changed

+76
-30
lines changed

alloc/src/lib.rs

+1
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,7 @@
114114
#![feature(const_option)]
115115
#![feature(const_pin)]
116116
#![feature(const_size_of_val)]
117+
#![feature(const_vec_string_slice)]
117118
#![feature(core_intrinsics)]
118119
#![feature(deprecated_suggestion)]
119120
#![feature(deref_pure_trait)]

alloc/src/raw_vec.rs

+6-6
Original file line numberDiff line numberDiff line change
@@ -280,7 +280,7 @@ impl<T, A: Allocator> RawVec<T, A> {
280280
/// `Unique::dangling()` if `capacity == 0` or `T` is zero-sized. In the former case, you must
281281
/// be careful.
282282
#[inline]
283-
pub fn ptr(&self) -> *mut T {
283+
pub const fn ptr(&self) -> *mut T {
284284
self.inner.ptr()
285285
}
286286

@@ -293,7 +293,7 @@ impl<T, A: Allocator> RawVec<T, A> {
293293
///
294294
/// This will always be `usize::MAX` if `T` is zero-sized.
295295
#[inline]
296-
pub fn capacity(&self) -> usize {
296+
pub const fn capacity(&self) -> usize {
297297
self.inner.capacity(size_of::<T>())
298298
}
299299

@@ -488,17 +488,17 @@ impl<A: Allocator> RawVecInner<A> {
488488
}
489489

490490
#[inline]
491-
fn ptr<T>(&self) -> *mut T {
491+
const fn ptr<T>(&self) -> *mut T {
492492
self.non_null::<T>().as_ptr()
493493
}
494494

495495
#[inline]
496-
fn non_null<T>(&self) -> NonNull<T> {
497-
self.ptr.cast().into()
496+
const fn non_null<T>(&self) -> NonNull<T> {
497+
self.ptr.cast().as_non_null_ptr()
498498
}
499499

500500
#[inline]
501-
fn capacity(&self, elem_size: usize) -> usize {
501+
const fn capacity(&self, elem_size: usize) -> usize {
502502
if elem_size == 0 { usize::MAX } else { self.cap.0 }
503503
}
504504

alloc/src/string.rs

+25-13
Original file line numberDiff line numberDiff line change
@@ -1059,7 +1059,8 @@ impl String {
10591059
#[inline]
10601060
#[must_use = "`self` will be dropped if the result is not used"]
10611061
#[stable(feature = "rust1", since = "1.0.0")]
1062-
pub fn into_bytes(self) -> Vec<u8> {
1062+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1063+
pub const fn into_bytes(self) -> Vec<u8> {
10631064
self.vec
10641065
}
10651066

@@ -1076,8 +1077,11 @@ impl String {
10761077
#[must_use]
10771078
#[stable(feature = "string_as_str", since = "1.7.0")]
10781079
#[cfg_attr(not(test), rustc_diagnostic_item = "string_as_str")]
1079-
pub fn as_str(&self) -> &str {
1080-
self
1080+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1081+
pub const fn as_str(&self) -> &str {
1082+
// SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1083+
// at construction.
1084+
unsafe { str::from_utf8_unchecked(self.vec.as_slice()) }
10811085
}
10821086

10831087
/// Converts a `String` into a mutable string slice.
@@ -1096,8 +1100,11 @@ impl String {
10961100
#[must_use]
10971101
#[stable(feature = "string_as_str", since = "1.7.0")]
10981102
#[cfg_attr(not(test), rustc_diagnostic_item = "string_as_mut_str")]
1099-
pub fn as_mut_str(&mut self) -> &mut str {
1100-
self
1103+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1104+
pub const fn as_mut_str(&mut self) -> &mut str {
1105+
// SAFETY: String contents are stipulated to be valid UTF-8, invalid contents are an error
1106+
// at construction.
1107+
unsafe { str::from_utf8_unchecked_mut(self.vec.as_mut_slice()) }
11011108
}
11021109

11031110
/// Appends a given string slice onto the end of this `String`.
@@ -1168,7 +1175,8 @@ impl String {
11681175
#[inline]
11691176
#[must_use]
11701177
#[stable(feature = "rust1", since = "1.0.0")]
1171-
pub fn capacity(&self) -> usize {
1178+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1179+
pub const fn capacity(&self) -> usize {
11721180
self.vec.capacity()
11731181
}
11741182

@@ -1431,8 +1439,9 @@ impl String {
14311439
#[inline]
14321440
#[must_use]
14331441
#[stable(feature = "rust1", since = "1.0.0")]
1434-
pub fn as_bytes(&self) -> &[u8] {
1435-
&self.vec
1442+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1443+
pub const fn as_bytes(&self) -> &[u8] {
1444+
self.vec.as_slice()
14361445
}
14371446

14381447
/// Shortens this `String` to the specified length.
@@ -1784,7 +1793,8 @@ impl String {
17841793
/// ```
17851794
#[inline]
17861795
#[stable(feature = "rust1", since = "1.0.0")]
1787-
pub unsafe fn as_mut_vec(&mut self) -> &mut Vec<u8> {
1796+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1797+
pub const unsafe fn as_mut_vec(&mut self) -> &mut Vec<u8> {
17881798
&mut self.vec
17891799
}
17901800

@@ -1805,8 +1815,9 @@ impl String {
18051815
#[inline]
18061816
#[must_use]
18071817
#[stable(feature = "rust1", since = "1.0.0")]
1818+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
18081819
#[rustc_confusables("length", "size")]
1809-
pub fn len(&self) -> usize {
1820+
pub const fn len(&self) -> usize {
18101821
self.vec.len()
18111822
}
18121823

@@ -1824,7 +1835,8 @@ impl String {
18241835
#[inline]
18251836
#[must_use]
18261837
#[stable(feature = "rust1", since = "1.0.0")]
1827-
pub fn is_empty(&self) -> bool {
1838+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1839+
pub const fn is_empty(&self) -> bool {
18281840
self.len() == 0
18291841
}
18301842

@@ -2565,7 +2577,7 @@ impl ops::Deref for String {
25652577

25662578
#[inline]
25672579
fn deref(&self) -> &str {
2568-
unsafe { str::from_utf8_unchecked(&self.vec) }
2580+
self.as_str()
25692581
}
25702582
}
25712583

@@ -2576,7 +2588,7 @@ unsafe impl ops::DerefPure for String {}
25762588
impl ops::DerefMut for String {
25772589
#[inline]
25782590
fn deref_mut(&mut self) -> &mut str {
2579-
unsafe { str::from_utf8_unchecked_mut(&mut *self.vec) }
2591+
self.as_mut_str()
25802592
}
25812593
}
25822594

alloc/src/vec/mod.rs

+44-11
Original file line numberDiff line numberDiff line change
@@ -1240,7 +1240,8 @@ impl<T, A: Allocator> Vec<T, A> {
12401240
/// ```
12411241
#[inline]
12421242
#[stable(feature = "rust1", since = "1.0.0")]
1243-
pub fn capacity(&self) -> usize {
1243+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1244+
pub const fn capacity(&self) -> usize {
12441245
self.buf.capacity()
12451246
}
12461247

@@ -1548,8 +1549,22 @@ impl<T, A: Allocator> Vec<T, A> {
15481549
#[inline]
15491550
#[stable(feature = "vec_as_slice", since = "1.7.0")]
15501551
#[cfg_attr(not(test), rustc_diagnostic_item = "vec_as_slice")]
1551-
pub fn as_slice(&self) -> &[T] {
1552-
self
1552+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1553+
pub const fn as_slice(&self) -> &[T] {
1554+
// SAFETY: `slice::from_raw_parts` requires pointee is a contiguous, aligned buffer of size
1555+
// `len` containing properly-initialized `T`s. Data must not be mutated for the returned
1556+
// lifetime. Further, `len * mem::size_of::<T>` <= `ISIZE::MAX`, and allocation does not
1557+
// "wrap" through overflowing memory addresses.
1558+
//
1559+
// * Vec API guarantees that self.buf:
1560+
// * contains only properly-initialized items within 0..len
1561+
// * is aligned, contiguous, and valid for `len` reads
1562+
// * obeys size and address-wrapping constraints
1563+
//
1564+
// * We only construct `&mut` references to `self.buf` through `&mut self` methods; borrow-
1565+
// check ensures that it is not possible to mutably alias `self.buf` within the
1566+
// returned lifetime.
1567+
unsafe { slice::from_raw_parts(self.as_ptr(), self.len) }
15531568
}
15541569

15551570
/// Extracts a mutable slice of the entire vector.
@@ -1566,8 +1581,22 @@ impl<T, A: Allocator> Vec<T, A> {
15661581
#[inline]
15671582
#[stable(feature = "vec_as_slice", since = "1.7.0")]
15681583
#[cfg_attr(not(test), rustc_diagnostic_item = "vec_as_mut_slice")]
1569-
pub fn as_mut_slice(&mut self) -> &mut [T] {
1570-
self
1584+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
1585+
pub const fn as_mut_slice(&mut self) -> &mut [T] {
1586+
// SAFETY: `slice::from_raw_parts_mut` requires pointee is a contiguous, aligned buffer of
1587+
// size `len` containing properly-initialized `T`s. Data must not be accessed through any
1588+
// other pointer for the returned lifetime. Further, `len * mem::size_of::<T>` <=
1589+
// `ISIZE::MAX` and allocation does not "wrap" through overflowing memory addresses.
1590+
//
1591+
// * Vec API guarantees that self.buf:
1592+
// * contains only properly-initialized items within 0..len
1593+
// * is aligned, contiguous, and valid for `len` reads
1594+
// * obeys size and address-wrapping constraints
1595+
//
1596+
// * We only construct references to `self.buf` through `&self` and `&mut self` methods;
1597+
// borrow-check ensures that it is not possible to construct a reference to `self.buf`
1598+
// within the returned lifetime.
1599+
unsafe { slice::from_raw_parts_mut(self.as_mut_ptr(), self.len) }
15711600
}
15721601

15731602
/// Returns a raw pointer to the vector's buffer, or a dangling raw pointer
@@ -1622,9 +1651,10 @@ impl<T, A: Allocator> Vec<T, A> {
16221651
/// [`as_mut_ptr`]: Vec::as_mut_ptr
16231652
/// [`as_ptr`]: Vec::as_ptr
16241653
#[stable(feature = "vec_as_ptr", since = "1.37.0")]
1654+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
16251655
#[rustc_never_returns_null_ptr]
16261656
#[inline]
1627-
pub fn as_ptr(&self) -> *const T {
1657+
pub const fn as_ptr(&self) -> *const T {
16281658
// We shadow the slice method of the same name to avoid going through
16291659
// `deref`, which creates an intermediate reference.
16301660
self.buf.ptr()
@@ -1681,9 +1711,10 @@ impl<T, A: Allocator> Vec<T, A> {
16811711
/// [`as_mut_ptr`]: Vec::as_mut_ptr
16821712
/// [`as_ptr`]: Vec::as_ptr
16831713
#[stable(feature = "vec_as_ptr", since = "1.37.0")]
1714+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
16841715
#[rustc_never_returns_null_ptr]
16851716
#[inline]
1686-
pub fn as_mut_ptr(&mut self) -> *mut T {
1717+
pub const fn as_mut_ptr(&mut self) -> *mut T {
16871718
// We shadow the slice method of the same name to avoid going through
16881719
// `deref_mut`, which creates an intermediate reference.
16891720
self.buf.ptr()
@@ -2561,8 +2592,9 @@ impl<T, A: Allocator> Vec<T, A> {
25612592
/// ```
25622593
#[inline]
25632594
#[stable(feature = "rust1", since = "1.0.0")]
2595+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
25642596
#[rustc_confusables("length", "size")]
2565-
pub fn len(&self) -> usize {
2597+
pub const fn len(&self) -> usize {
25662598
self.len
25672599
}
25682600

@@ -2579,7 +2611,8 @@ impl<T, A: Allocator> Vec<T, A> {
25792611
/// ```
25802612
#[stable(feature = "rust1", since = "1.0.0")]
25812613
#[cfg_attr(not(test), rustc_diagnostic_item = "vec_is_empty")]
2582-
pub fn is_empty(&self) -> bool {
2614+
#[rustc_const_unstable(feature = "const_vec_string_slice", issue = "129041")]
2615+
pub const fn is_empty(&self) -> bool {
25832616
self.len() == 0
25842617
}
25852618

@@ -3130,15 +3163,15 @@ impl<T, A: Allocator> ops::Deref for Vec<T, A> {
31303163

31313164
#[inline]
31323165
fn deref(&self) -> &[T] {
3133-
unsafe { slice::from_raw_parts(self.as_ptr(), self.len) }
3166+
self.as_slice()
31343167
}
31353168
}
31363169

31373170
#[stable(feature = "rust1", since = "1.0.0")]
31383171
impl<T, A: Allocator> ops::DerefMut for Vec<T, A> {
31393172
#[inline]
31403173
fn deref_mut(&mut self) -> &mut [T] {
3141-
unsafe { slice::from_raw_parts_mut(self.as_mut_ptr(), self.len) }
3174+
self.as_mut_slice()
31423175
}
31433176
}
31443177

0 commit comments

Comments
 (0)